Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Code Review 7Review code for quality, security, and style using structured checklists. Use when reviewing PRs, giving feedback on code, or auditing code quality. Use when this capability is needed.
-
tomevault-io Bundle Security Audit 2Use this skill to perform a security-focused audit of the codebase to identify vulnerabilities, sandbox escapes, and logic flaws.
-
tomevault-io Bundle Review 13Comprehensive code review for PRs or recent changes. Checks correctness, security, performance, maintainability, and tests. Use when this capability is needed.
-
tomevault-io Bundle Audit 3Review AI-drafted issues for human approval Use when this capability is needed.
-
tomevault-io Bundle Code Review 59Perform thorough code reviews following best practices, identify bugs, security issues, and suggest improvements. Use when this capability is needed.
-
tomevault-io Bundle Security 5Security best practices for web applications. Use when implementing authentication, authorization, input validation, or reviewing code for vulnerabilities. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 10Staff-engineer-level code review delivering 10 prioritized actionable findings across architecture, security, performance, and maintainability Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 11Thorough code review with security analysis and best practices Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 13Use when working with a skill that helps review code for best practices, bugs, and security issues
-
tomevault-io Bundle Code Review 66Perform code reviews following best practices from Code Smells and The Pragmatic Programmer. Use when asked to "review this code", "check for code smells", "review my PR", "audit the codebase", or need quality feedback on code changes. Supports both full codebase audits and focused PR/diff reviews. Outputs structured markdown reports grouped by severity. Use when this capability is needed.
-
tomevault-io Bundle Audit 5On-demand security and code quality audit. Use when checking for vulnerabilities, security issues, code smells, or compliance problems. Trigger keywords - "audit", "security check", "vulnerability scan", "code quality", "compliance", "security audit". Use when this capability is needed.
-
tomevault-io Bundle Healthcheck 4Host security hardening and risk-tolerance configuration for OpenSoul deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenSoul cron scheduling for periodic checks, or version status checks on a machine running OpenSoul (laptop, workstation, Pi, VPS). Use when this capability is needed.
-
tomevault-io Bundle Doc Sync 2Synchronizes CLAUDE.md navigation indexes and README.md architecture docs across a repository. Use when asked to "sync docs", "update CLAUDE.md files", "ensure documentation is in sync", "audit documentation", or when documentation maintenance is needed after code changes. Use when this capability is needed.
-
tomevault-io Bundle Plugin Dev 2Validate plugin SKILL.md frontmatter and audit hook scripts for silent failures. Run validation to check all plugins pass schema, source path, and frontmatter checks. Run hook audit to detect unhandled errors in shell and Python scripts. Use when this capability is needed.
-
tomevault-io Bundle Code Review 70Review ServiceNow server-side scripts for ES5 violations, ACL/injection/XSS issues, N+1 queries, missing setLimit/error handling, hard-coded sys_ids, and business-rule recursion risks. Use when this capability is needed.
-
tomevault-io Bundle Security 7Use when auditing security, checking for vulnerabilities, scanning for secrets, or reviewing dependencies. OWASP Top 10 audit with GitLeaks and dependency checks.
-
tomevault-io Bundle Code Review 92Review code for type safety, idiomatic style, architecture, security, and performance, with concrete fixes (not vague nits). Trigger this whenever the user asks to "review", "check", "look over", "audit", "find issues in", or "PR review" some code, or pastes a diff and asks what's wrong. Works on any language with deeper Python checks (Google style, ruff, ty, PEP compliance) when the target is Python. Outputs severity-ranked findings with line numbers and before/after code. Use when this capability is needed.
-
tomevault-io Bundle IOS 3Skills for iOS application security testing including IPA analysis, data storage, and runtime manipulation. Use when this capability is needed.
-
tomevault-io Bundle Healthcheck 5Host security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS). Use when this capability is needed.
-
tomevault-io Bundle Security 8Security best practices for secure coding, authentication, authorization, and data protection. Use when developing features that handle sensitive data, user authentication, or require security review. Use when this capability is needed.
-
tomevault-io Bundle Security 9This skill should be used when auditing code for security issues, reviewing authentication/authorization, evaluating input validation, analyzing cryptographic usage, or reviewing dependency security. Provides OWASP patterns, CWE analysis, and threat modeling guidance. Use when this capability is needed.
-
tomevault-io Bundle Ship 9Ship current branch — CI, SonarCloud, code review, security review, fix all issues, merge. Assumes code is already committed and pushed. Use when this capability is needed.
-
tomevault-io Bundle Healthcheck 6Security audit and environment hardening. Use when asked about security, system health, or deployment safety. Use when this capability is needed.
-
tomevault-io Bundle Security Review 3Scan code changes for security vulnerabilities using STRIDE threat modeling, validate findings for exploitability, and output structured results for downstream patch generation. Supports PR review, scheduled scans, and full repository audits. Use when this capability is needed.
-
tomevault-io Bundle Validation 3Validate code quality, test coverage, performance, and security. Use Use when this capability is needed.
-
tomevault-io Bundle Code Review 105Pre-commit gate. Reviews staged or branch-scoped diff for security issues, quality regressions, and adherence to project conventions. Auto-fixes safe items; flags judgment calls. Reads CLAUDE.md / AGENTS.md / DESIGN.md as the convention source. Use when this capability is needed.
-
tomevault-io Bundle Code Review 106Proactive code quality review. Triggers on significant code changes to check security, performance, architecture, and project patterns. Use when this capability is needed.
-
tomevault-io Bundle Sync Docs 3Audit and synchronize all project documentation after code changes. Ensures README, copilot-instructions, AGENTS.md, developer guide, and operations guide stay accurate and consistent. Use when this capability is needed.
-
tomevault-io Bundle Review 33Code review workflow. Reviews code quality, security, performance. Use for PR reviews or code audits. Use when this capability is needed.
-
tomevault-io Bundle Code Review 119Reviews generated or modified code for correctness, maintainability, boundaries, security, tests, dependencies, naming, error handling, and hallucinated APIs. Use when this capability is needed.
-
tomevault-io Bundle Code Reviewer 21Review code for best practices, potential bugs, security vulnerabilities, and performance issues Use when this capability is needed.
-
tomevault-io Bundle Review Deps 2Audit project dependencies for vulnerabilities, license compliance risks, Use when this capability is needed.
-
tomevault-io Bundle Skill Creator 74Create, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory (moving files to references/ or scripts/, removing stale content, validating against the AgentSkills spec). Triggers on phrases like "create a skill", "author a skill", "tidy up a skill", "improve this skill", "review the skill", "clean up the skill", "audit the skill". Use when this capability is needed.
-
tomevault-io Bundle Security Audit 6Codebase-wide security analysis including dependencies, secrets, and OWASP Top 10 vulnerabilities. Use when this capability is needed.
-
tomevault-io Bundle Simple Skill 3Use when working with a simple and safe skill for code review
-
tomevault-io Bundle Release 64Release preparation workflow - security audit → E2E tests → review → changelog → docs Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-review, security-audit, review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.